Bring more noise to @zachxbt’s community alert below
I hope in the future these companies, (including @revolut) which are so obliged and eager to KYC you while at the same time being masters of your money in uncomfortable ways, are held accountable in court for the wrench attacks that will be proven to be directly correlated to their negligence
—
Community alert: Revolut appears to have exposed personally identifiable information (PII) for a subset of users due to failing to detect a fraudulent government request.
Exposed data included:
-Copy of passport and/or driver's licence, plus the verification selfie
-Account statements, IBAN, withdrawal records, and full transaction history including Bitcoin
-Full name, date of birth, occupation
-Home address, email, phone number
While the incident is likely limited in size it seems to have been targeted at high net worth users.
An email alerting users was sent out to multiple Revolut users yesterday.
2/ On April 17, 2026, five attackers carried out a violent home invasion robbery against a victim in France, stealing ~7.2 BTC ($557K). Several people were sent to the hospital.
Theft address
bc1qrdq5acl9nw4gt3cjte2629lw9qcg9xxkf3x02k
1/ Meet Tiffany Milanovich, a US based threat actor tied to at least $5M in thefts from hardware wallet and centralized exchange support impersonation scams.
She's recorded herself taunting victims on calls after draining their funds.
Tiffany openly flaunts luxury purchases, stolen funds, and casino gambling on social media.
2/ Tiffany operates as a 'caller' the person who phones victims posing as exchange or wallet support and talks them into handing over access to their funds.
In the clip below, you can hear what one of her calls sounds like.
A short story about Indian scammers who called the cops on themselves:
Earlier this week a follower DM'd me from his personal account complaining that 5.73 BTC ($475K) of his was 'unjustly' frozen at Changelly in Mar 2025.
So I went and plotted the Bitcoin transaction in my compliance tools.
The inflows trace back to illicit sources via social engineering thefts targeting Americans through US exchanges and Bitcoin ATMs.
The broader cluster of high confidence thefts has taken $1M+ from victims since 2025, with several of them elderly.
His story kept changing. It was a loan. No, his boss sent it. No, his boss invested in Bitcoin "during 2014 and 2015" through a friend in the US.
The best part? In Dec 2025 he claims to have filed a police report in India over these frozen funds (3207-P/2025).
In our DMs he shared email screenshots which I queried to surface more data points and map his group out.
I suspect AmanKesar11 is a mule for his boss 'Mr Parveen,' as the 'proof' he sent included bank statements under a different name / location.
While you can message me for help and I'll respect your privacy, at least use common sense and don't contact me with stolen funds.
5.73 BTC frozen order: fb931baac66bfc116deb10fa81417fb3da61e4362cd2997ee1eaa577e96272f3
AmanKesar11 BTC address: bc1q5yjxzcvfswvyx9y6cvlc3xe4laqqnqsjp3f9t2
AmanKesar11 Tron address: TQkEVXjtvSbigGa5fqFUpcYJnGvpKPPBEm
2/ LAB was founded by Vova Sadkov & Mark as a trading platform and TGE'd in Oct 2025. Their prior project Eesee ($ESE) left investors feeling abandoned after the team moved on.
There's no clear LAB token distribution available. Coingecko, RootData, & CMC all report different floats, and the LAB docs themselves provide zero details on the breakdown.
Backers include Lemniscap, OKX, Animoca, GSR, Gate, Kucoin, Mirana, & Amber. Several are also the exchanges where the token trades.
Based on my analysis of onchain activity, insiders likely control >95% of supply currently.
1/ Meet Dritan Kapllani Jr, a US based threat actor tied to $19M from social engineering thefts targeting crypto holders.
Dritan flexes luxury cars, watches, private jets, & clubs all over social media.
Recently he was recorded on a call showing off a wallet with stolen funds.
2/ Dritan was caught flexing $3.68M on his Exodus wallet during a band 4 band (B4B) on a Discord call on April 23, 2026, trying to prove he had more money than another threat actor.
Dritan's ETH address: 0x4487db847db2fc99372a985743a26f46e0b2bba6
Discord ID: 1485730459483902103
1/ The $150M+ DSJ Exchange (DSJEX) / BG Wealth Sharing Ponzi scheme collapsed last week. From April 27 – May 3, illicit actors laundered $92M+ across chains to obscure the trail.
I helped lead an initiative with @Tether_to, @Binance Security Team, @OKX, & US law enforcement that has since frozen $41.5M+.
2/ DSJ / BG has been running since 2025, advertising 1.3% - 2.6% daily returns with referral commissions and rank-based bonuses.
DSJ = fake trading platform
BG = investment group
A fictitious CEO named Stephen Beard fronted the platform, while domains and hot wallets rotated regularly to evade law enforcement.
Recruitment and fake trading signals was pushed through a group on BonChat (Hong Kong messaging app).
h/t @dehek & BehindMLM for early coverage of the investment fraud.
In late 2023, French streamer TeufeurS was extorted for a ransom after a family member was kidnapped in France.
I can finally share that I helped lead efforts that resulted in an ~$800K freeze with the Binance Security team after a $2M ransom was paid.
Six suspects tied to the incident were later arrested. Given the sensitivity of the case, I held off commenting until now.
I have since assisted with asset freezes and identifying culprits in several of the recent France home invasion robberies, and hope to share details in the coming months.
If you or someone you know falls victim, reach out as soon as possible rather than delay.
I prioritize these types of cases as they have grown more frequent amidst this disturbing trend.
If you enjoy similiar type of work from me consider participating in the @thedaofund x @Giveth 500 ETH matching round for Ethereum Security which is live until May 15.
It's quadratic funding, so smaller contributions are worth considerably more.
Currently a $10 donation is >$5K matched.
Link to support me:
https://t.co/aCIuQPZvOA
A summary of the RAVE -95% price fluctuation from $26 to $1 over the past 24 hours.
RAVE Timeline: April 18, 2026
7:26 am UTC: I posted a call to action for Binance, Bitget, & Gate to investigate RAVE market manipulation and offered a $10K bounty.
10:56 am UTC: I posted an update increasing the bounty to $25K.
11:18 am UTC: Bitget publicly acknowledged the call to action.
2:08 pm UTC: Binance publicly acknowledged the call to action.
3:06 pm UTC: RaveDAO posted claiming they have no involvement.
4:19 pm UTC: Gate publicly acknowledged the call to action.
In the days leading up, on April 13 & 14, I confronted RaveDAO co-founder Yemu Xu (wildwoomoo) but have yet to receive an answer.
RAVE launched in Dec 2025 on Binance Alpha with a 1B total supply. The addresses below, linked to the initial distribution, control ~95% of the RAVE supply (h/t Mlm):
0x9831156F1a6E506Fca41503590b42F07c2e80f54
0x8Ed6245C3276307E1A9D9Dc872E98A0E770070fd
0x6020656d1EF182173E45D4Fc375BDD5a48c674B0
0x2664cB80a5ee7D8EC05fe7C752dD62E078056E6d
0x2D81F8AeBf3e58A5e638006c9fd8F38C5220ecab
0x31694d761A8e851cFFbCd286aC54D01e5Ce5aFe6
0x0A1F07993a51CcEb4f52CA67765AECeADDA790d7
0xEB74Df8588cFC1C179Df4bd96C0bB8B227B9bE92
0x53d7d52301366DC14E1916b14eFeC1aDD8F3487b
I found suspicious CEX activity in April 2026 tied to RaveDAO team addresses onchain, which potentially contradicts their recent statement:
Bitget
0x2dc20f2180582172f5450c5d71e23fa438a7031b
0xa3a02aeb97fc1737c66f50d07d024799c137891d
0x2d95eb42525e6087e0cb7869f98da6838ed2e743
Gate
0x31711246b05d71e9eda5e38a3abb654020ee3353
Given the supply concentration, the team at minimum knows who is responsible for this price action.
A simple litmus test: $6B in market cap was wiped out on just $52M of 24hr liquidations (h/t CoinGlass). That ratio points to a manipulated and unsustainable valuation.
RAVE is not the only token with manipulation we have seen on major centralized exchanges. It's just the most blatant, reaching a top 15 market cap within 10 days before dropping 95% in hours.
Other projects with highly questionable price action recently include: SIREN, MYX, COAI, M, PIPPIN, RIVER.
Exchanges need faster intervention on manipulation. Detection at scale isn't easy, but each day of delay means retail traders absorb losses while platforms collect fees on the volume. The outcome is the same regardless of intent.
While it's good the exchanges responded, I find it unlikely this activity wasn't spotted internally before I raised it publicly.
I recognize how much this behavior takes from retail traders, and I plan to investigate similar movements in hopes of identifying the responsible parties.
I want to reiterate that I did not take a position. If I had, I would have been liquidated myself. I also could not anticipate if or when the exchanges would comment publicly.
My $25K bounty will remain active since the only DMs received were unverified claims rather than non-public information with supporting evidence as requested.
Update: Three hours ago multisig 0x53d7 linked to the RAVE initial distribution which I flagged above sent ~23M RAVE ($23M) to two Bitget deposit addresses and the price dropped 40% from $1 to $0.6.
Deposit addresses
0x26aC542f5a04D574580881723224DAcD1EDB9B45
0x64D6E91D0bd9cB7be44E1e627264539493f73c2b
1/ Meet M1llionz (RichMilly666), a French cybercriminal allegedly laundering assets from two violent home invasion robberies in France in April 2026 that netted $667K total, with a history of openly posting about bank and retail fraud on social media.
My work has led to a $93K Tether freeze directly tied to these attacks so far.
Everything after this is tracing, freeze requests, and exchange follow-ups. It takes time. Sometimes it goes nowhere. No one can promise a timeline.
If anyone tells you otherwise, they're selling you something.
If you've been hit, post the tx hash in this thread. We'll look at what's traceable.
Monitoring another wave of drainers today. Their opsec is incredibly lazy, reusing the exact same consolidation contracts and tx routes to bridge out. If you got hit, your window is about 60 minutes before the funds hit a mixer.
Run this triage protocol immediately. 🧵
The predatory aftermath of an exploit is predictable. Within minutes, "recovery specialists" flood the timeline. Most are secondary scams preying on panic.
Credible investigators don't cold-DM victims. Neither do we. We work through inbound consultations only.
Stay sharp. If someone messages you out of nowhere promising vague recovery, block them.
You come to us. Never the other way around.